Asking "is it malware?" before downloading is rational. Clash Verge Rev is an open-source desktop proxy client on GitHub—not a trojan. AV alerts are often heuristic: it changes system proxy, installs a virtual adapter, and may lack familiar notarization.
Detection ≠ confirmed malware. Real risks: fake sites, bundles, "cracked" builds, and leaking subscription URLs. Install only from the download center.
Why AV flags it
Proxy tools look "suspicious." Prefer publisher checks and checksums over mystery "undetected" repacks.
Real risk surface
- Trojanized installers.
- Allow LAN on untrusted networks (LAN share).
- Untrusted providers (choose a provider).
Service mode, Tun, firewall
Permission vs false positive (Tun start failed, Tun & AI). macOS "damaged" is Gatekeeper (macOS damaged).
After install
Version matches the download page; no surprise browser hijacks; uninstall restores networking (cleanup). Start: getting started, install by OS.
False positive vs real threat
| Signal | Likely meaning |
|---|---|
| AV blocks on first run, vendor-signed build from this site | Heuristic false positive |
| Offshore mirror with no checksum and "pre-cracked" tag | Genuine risk |
| Installer asks for your subscription URL then phones home | Suspect; verify source |
| macOS "damaged" dialog only | Gatekeeper, not malware |
When in doubt, compare the file hash against the official release and reinstall from the download center rather than a random mirror.